Where
AND
-Infinity
0
Severity
7.5
Input Validation
AV:N/AC:L/Au:N/C:P/I:P/A:P

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.

First published (updated )
Severity
6.8
Path Traversal
AV:N/AC:L/Au:S/C:C/I:N/A:N

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

First published (updated )
Severity
6.8
Input Validation
AV:N/AC:M/Au:N/C:P/I:P/A:P

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the opensslverify function, which allows remote attackers to bypass validation via a crafted certificate.

First published (updated )
Severity
6.8
CSRF
AV:N/AC:M/Au:N/C:P/I:P/A:P

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

First published (updated )
Severity
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.

First published (updated )
Severity
6.5
Input Validation
AV:N/AC:L/Au:S/C:P/I:P/A:P

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

First published (updated )
Severity
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.

First published (updated )
Severity
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

1 / 3
Source: GitHub
First published (updated )
Severity
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

First published (updated )
Severity
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories, which allows remote authenticated users to read, modify, or delete arbitrary site-wide repositories by leveraging certain read access.

First published (updated )
Severity
6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

First published (updated )
Severity
6.4
AV:N/AC:L/Au:N/C:P/I:N/A:P

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

First published (updated )
Severity
5.5
AV:N/AC:L/Au:S/C:P/I:P/A:N

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

First published (updated )
Severity
5.5
AV:N/AC:L/Au:S/C:N/I:P/A:P

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.

First published (updated )
Severity
5.5
AV:N/AC:L/Au:S/C:N/I:P/A:P

mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.

First published (updated )
Severity
5.5
AV:N/AC:L/Au:S/C:N/I:P/A:P

backup/moodle2/restorestepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

First published (updated )
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/casform.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbitrary user accounts via unspecified vectors.

First published (updated )
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:P/A:N

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.

1 / 2
Source: GitHub
First published (updated )
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the absolute path in an exception message.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comments, which allows remote attackers to obtain sensitive information via a crafted request.

First published (updated )
Severity
5
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:N

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:P/A:N

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

1 / 2
Source: GitHub
First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

First published (updated )
Severity
5
XSS
AV:N/AC:L/Au:N/C:P/I:N/A:N

A number of flaws have been fixed in new upstream Moodle 2.1.2, 2.0.5, and 1.9.14. These do not have CVEs assigned (request pending), and since Fedora/EPEL will rebase to the latest versions of each branch, I'm summarizing them all here rather than creating 16 separate bugs:

MSA-11-0041: Global search authentication issue Affects: 2.1.x 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=5eb1cec34f013fdcb559b66bc401f2845ce0bbb7 Reference: http://moodle.org/mod/forum/discuss.php?d=188323

MSA-11-0040: Potential personal information leak Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&s=MDL-28615 Reference: http://moodle.org/mod/forum/discuss.php?d=188322

MSA-11-0039: Wiki section vulnerability Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=41017112cff7f5bd7969c72d321320f3090e7c68 Reference: http://moodle.org/mod/forum/discuss.php?d=188321

MSA-11-0038: Database injection protection strengthened Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=4a2acd8c7e6c869d5fd5aa686e6e0a3f20c97f15 Reference: http://moodle.org/mod/forum/discuss.php?d=188320

MSA-11-0037: Course section editing injection vulnerability Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=4a2acd8c7e6c869d5fd5aa686e6e0a3f20c97f15 Reference: http://moodle.org/mod/forum/discuss.php?d=188319

MSA-11-0036: Messaging refresh vulnerability Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=97f258fabb3ebfa7acc7c02cb59de92b01710f99 Reference: http://moodle.org/mod/forum/discuss.php?d=188318

MSA-11-0035: Cookie-less session vulnerability Affects: 2.1.x, 2.0.x, (1.9.x if misconfigured) Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=e1e082a809b9a2d3a408cb4d6faa34fdfcf3165c Reference: http://moodle.org/mod/forum/discuss.php?d=188317

MSA-11-0034: Chat module information leak Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=d0157d827bc254ba386a5e5b41b13be2698ee76e Reference: http://moodle.org/mod/forum/discuss.php?d=188316

MSA-11-0033: Site-hub registration identity issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=ca896fdfcfcc87846fa91a297d0aa6999a68c48a Reference: http://moodle.org/mod/forum/discuss.php?d=188315

MSA-11-0032: MNET SSL validation issue Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=54941685e3e86ec085641dcb7ebb1f96f06735b2 Reference: http://moodle.org/mod/forum/discuss.php?d=188314

MSA-11-0031: Forms API constant issue Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=f1f70bd4dde6cd1ea4bdb8ab28fa3d36a53b89d8 Reference: http://moodle.org/mod/forum/discuss.php?d=188313

MSA-11-0030: Box.net repository integration authentication issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=3deff6c9d2bb4ab3144b3ca7b93d6a2ef6a87af2 Reference: http://moodle.org/mod/forum/discuss.php?d=188312

MSA-11-0029: File visibility issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=f6b07c4da54a9db24723beb147e8a19a3d487e00 Reference: http://moodle.org/mod/forum/discuss.php?d=188311

MSA-11-0028: Wiki comments XSS issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=a459fd90625ae44d7b3ac10b65da2dc631a418e7 Reference: http://moodle.org/mod/forum/discuss.php?d=188310

MSA-11-0027: Wiki pages reference forgery issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=48346fb11f8ced06a05c0618b02a3a925b34ec59 Reference: http://moodle.org/mod/forum/discuss.php?d=188309

MSA-11-0026: Fields in user upload CSV not being escaped Affects: 1.9.x Reference: http://moodle.org/mod/forum/discuss.php?d=182743

1 / 3
Source: Red Hat
First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:P/A:N

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

First published (updated )
Severity
5
CRLF Injection
AV:N/AC:L/Au:N/C:N/I:P/A:N

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203